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-Abstract- 

In a recent work, we introdnced four variants of diagnosability (FA, lA, FF, IF) in (finite) probabil¬ 
istic systems (pLTS) depending whether one considers (1) hnite or inhnite runs and (2) faulty or 
all runs. We studied their relationship and established that the corresponding decision problems 
are PS PACE-complete. A key ingredient of the decision procedures was a characterisation of 
diagnosability by the fact that a random run almost surely lies in an open set whose specihcation 
only depends on the qualitative behaviour of the pLTS. Here we investigate similar issues for 
inhnite pLTS. We hrst show that this characterisation still holds for FF-diagnosability but with 
a Gs set instead of an open set and also for IF- and lA-diagnosability when pLTS are hnitely 
branching. We also prove that surprisingly FA-diagnosability cannot be characterised in this 
way even in the hnitely branching case. Then we apply our characterisations for a partially ob¬ 
servable probabilistic extension of visibly pushdown automata (POpVPA), yielding EXPSPACE 
procedures for solving diagnosability problems. In addition, we establish some computational 
lower bounds and show that slight extensions of POpVPA lead to undecidability. 

[Y] Introduction 

Diagnosis. Monitoring (hardware and/or software) systems prone to faults involves several 
critical tasks: controlling the system to prevent faults as much as possible, deducing the cause 
of the faults, etc. Most of these tasks assume that an observer has the capability to assess the 
status of the current run based on the outputs of the system: providing information about 
the possible occurrence of faults. Such an observer is called a diagnoser and its associated 
task is called diagnosis. This framework leads to interesting decision and synthesis problems: 
“Does there exist a diagnoser?” and in the positive case “How to build such a diagnoser?”, 
“Which kind of diagnoser is sufficient?”, etc. The decision problem, on which we focus here, 
is called diagnosability [14]. 

Diagnosis of discrete event systems. In order to formally reason about diagnosability, the 
systems were first modelled by finite labelled transition systems (LTS). Then the specification 
of a diagnoser is defined by two requirements: correctness, meaning that the information 
provided by the diagnoser is accurate, and reactivity, ensuring that a fault will eventually 
be detected. Within the framework of finite LTS, the decision problem was shown to be 
solvable in PTIME [9] and it is in fact NLOGSPACE-complete. 

Diagnosis of probabilistic systems. A natural way of modelling partially observable 
systems consists in introducing probabilities {e.g. when the design is not fully known or 
the effects of the interaction with the environment is not predictible). Thus the notion 
of diagnosability was later extended to Markov chains with labels on transitions, also 
called probabilistic labelled transition systems (pLTS) [15]. In this context, the reactivity 
requirement now asks that faults will be almost surely eventually detected. Regarding 
correctness, two specifications have been proposed: either one sticks to the original definition 
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and requires that the provided information is accurate, defining A-diagnosability, or one 
weakens the correctness by admitting errors in the provided information that should, however, 
have an arbitrary small probability defining A A-diagnosability. From a computational 
viewpoint, we recently proved that A-diagnosability is PS PACE-complete [3] and that AA- 
diagnosability can be solved in PTIME [4]. 

In case a system is not diagnosable, one may be able to control it, by forbidding some 
controllable actions, so that is becomes diagnosable. This property of active diagnosability has 
been studied for discrete-event systems [13, 8], and for probabilistic systems [2]. Interestingly, 
the diagnosability notion in the latter work slightly differs from the original one in [15]. 
Building on this variation, in [3] semantical issues have been investigated and four relevant 
notions of diagnosability (FA, I A, FF, IF) have been defined depending on (1) whether one 
considers finite or infinite runs and (2) faulty or all runs. In finite pLTS, it was shown that 
all these notions can be characterized by the fact that a random run almost surely lies in an 
open set, whose specification only depends on the qualitative behaviour of the pLTS. 
Diagnosis of infinite-state systems. Diagnosability in infinite-state systems has been 
studied, on the one hand for restricted Petri nets [5], for which an accurate diagnoser can 
be designed, and on the other hand for visibly pushdown automata (VPA) [11], for which 
diagnosability can be decided via the determinisation procedure of [1]. However to the best 
of our knowledge diagnosis of probabilistic infinite-state systems has not yet been studied. 
Contributions. The characterisations of diagnosability established in [3] strongly relied 
on the finiteness of the models. Our first aim is thus to establish characterisations in the 
infinite-state case. FF-diagnosability (the original notion of diagnosability) states that almost 
surely a faulty run will be detected in finite time. We establish that FF-diagnosability 
can be characterised by the fact that a random run almost surely lies in a Gs set, only 
depending on the qualitative behaviour of the system. This characterisation also applies 
to I F-diagnosability for finitely-branching systems, since then the two notions coincide. An 
ambiguous infinite correct (resp. faulty) run is a run indistinguishable from a faulty (resp. 
correct) run. lA-diagnosability states that almost surely a run is unambiguous. The set 
of ambiguous runs is an analytic set (so a priori not known to be a Borel set). However 
in the finitely-branching case, we establish that the set of unambiguous runs is a Gs set, 
yielding a characterisation of lA-diagnosability. FA-diagnosability states that the probability 
that a finite run is unambiguous goes to 1 when its length goes to infinity. Surprisingly, 
despite the fact that lA-diagnosability and FA-diagnosability are very close, we prove that 
FA-diagnosability cannot be characterised by the fact that a random run almost surely lies in 
a Gs set. Furthermore we strenghten this result by another inexpressivess result also related 
to FA-diagnosability. 

We then introduce partially observable probabilistic visibly pushdown automata (POpVPA), 
a model generating infinite-state probabilistic systems. We show how to exploit the above 
characterisations to design a decision procedure for diagnosability in POpVPA. More precisely 
we show that we can “encode” our characterisations in an enlarged probabilistic VPA and 
then exploit the decision procedures of [7] leading to an EXPSPACE algorithm. Since our 
characterisations are not regular, this requires some tricky machinery. Finally we complete 
this work by exhibiting an EXPTIME lower-bound and showing that slight extensions of 
POpVPA lead to undecidability of the diagnosability problem. 

Organisation. In Section 2, we successively introduce probabilistic infinite-state systems, 
equip them with partial observation and faults, and define diagnosability notions. In Section 3, 
we establish characterisations of the diagnosability notions and inexpressiveness results. We 
exploit the characterisations to design decision procedures for POpVPA in Section 4, also 
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proving hardness and undecidability results. We conclude and give some perspectives in 
Section 5. All the proofs are given in Appendix. 

Diagnosis specifications of infinite-state probabilistic systems 
2.1 Probabilistic labelled transition systems 

Probabilistic labelled transition systems (pLTS) are labelled transition systems equipped 
with probability distributions on transitions outgoing from a state. 

► Definition 1. A pLTS is a tuple M = {Q, qo,S,T,P} where: 

H Q is a finite or countable set of states with qo e Q the initial state; 

B S is a finite set of events; 

H TsQxSxQisa set of transitions; 

H P : r -»• Q>o is the transition probability fulfilling: Vq 6 Q, E(g,a,g')6T P[9i9^ = 1- 

Given a pLTS A4, the transition relation of the underlying LTS C is defined hy q ^ q' 
for (q,a,q') e T; this transition is then said to be enabled in q. In order to emphasise the 
relation between the pLTS and the LTS, we sometimes write Ai = {C, P). Note that since we 
assume the state space to be at most countable, a pLTS is by definition at most countably 
branching: from every state q, there are at most countably many transitions enabled in q. 

► Example 2. The pLTS of Figure 1 represents a server that accepts jobs (event in) until it 
randomly decides to serve the jobs (event serve). When a job is done the result is delivered 
(event out). When all jobs are done, the server waits for a new batch of jobs. However 
randomly, the server may trigger a fault (event f) and then abort all remaining jobs (event 
abort). Afterwards, the server is reset (event reset). In the figure, the label of a transition 
(q, a, q') is depicted as P[q, a, q'] • a. 


1 •reset 


H Figure 1 An infinite-state pLTS. 

Let us now introduce some important notions and notations that will be used throughout 
the paper. A run p of a pLTS is a (finite or infinite) sequence p = qoooqi... such that 
for all i, qi € Q, m € Y, and when q.^+i is defined, qt -A q^+i. The notion of run can be 
generalised, starting from an arbitrary state q. We write H for the set of all infinite runs of 
A4 starting from qo, assuming the pLTS is clear from context. When it is finite, p ends in 
a state q and its lengthy denoted |p|, is the number of events occurring in it. Given a finite 
run p = qoooqi .. .q-a and a (finite or infinite) run p' = qnOnqn+i. •we call concatenation of 
p and p' and we write pp' the run qoOoqi... q„a„q„+i...; the run p is then a prefix of pp', 
which we denote p < pp'. The cylinder defined by a finite run p is the set of all infinite runs 
that extend p: C'(p) = {p' € fl | p < p'}. Gylinders are a basis of open sets for the standard 
topology on the set of runs (which can be viewed as an infinite tree). One equips a pLTS 
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with a probability measure on fl with a-algebra being B, the set of Borel sets, and which is 
uniquely defined by Caratheodory’s extension theorem from the probabilities of the cylinders: 

V{C{qoaoqi = P[qo,ai,qi]---P[qn-i,an-i,qn] ■ 

We will sometimes omit the C and write P(p) for P(C'(p)). It is well-known that once the 
measure is fixed, one can enlarge the set of of measurable sets by considering the smallest 
CT-algebra containing B and the “null” sets: {A \ 3B e B Ac B a P(_B) = 0} and then extend 
the original measure to a (complete) measure on this enlarged cr-algebra. We consider this 
measure in the sequel. 

The sequence associated with p = qa^qi ... is the word Cp = apai..., and we write 
indifferently q or q —(resp. q -^*q' or q —^*q') for an infinite (resp. finite) run p. A 
state q is reachable (from q^) if there exists a run such that q^ ■^*q, which we alternatively 
write qo —*•*(?. The (infinite) language of pLTS A4 consists of all infinite words that label 
runs of A4 and is formally defined as L“'(AI) = {a e | go }• 

2.2 Partial observation and faults 

The observation of a pLTS is given by a mask function. This function projects every event 
to its observation. This observation is partial as an event can have no observation or shares 
its observation with another event, but it is deterministic. 

► Definition 3. A partially observable pLTS (POpLTS) is a tuple Af = {M,T,o,V) consisting 
of a pLTS A4 equipped with a mapping 7^ : S ^ So u {s} where Sq is the set of observations. 

Note that our setting generalises most existing frameworks of fault diagnosis by considering 
a mask function V onto a possibly different alphabet rather than a partition of the event 
alphabet into observable and unobservable events. An event a e S is said unobservable if 
V{a) = e, fully observable if V{a) + e and ’P~^({’P(a)}) = {a} and partially observable if 
V{a) + e and |’P^^({’P(a)})| > 1. The set of unobservable events is denoted S„. 

Let cr € S* be a finite word; its length is denoted \a\. The mapping V is extended to finite 
words inductively: V{e) = e and V{aa) = V{a)V{a). We say that V{a) is the mask of cr. 
Write \a\o for \'P{a)\. When a is an infinite word, its mask is the limit of the masks of its 
finite prefixes. This mask function is applicable to runs via their associated sequence; it can 
be either finite or infinite. As usual the mask function is extended to languages. With respect 
to V, a POpLTS A/” is convergent if there is no infinite sequence of unobservable events 
from any reachable state: L“'(Ad) n = 0. When Af is convergent, for every a e L“'(Ad), 
V{a) 6 Sq . In the rest of the paper we assume that POpLTS are convergent. V can also be 
be viewed as a mapping from runs to 2“ by defining V{qoaoqiai ...) = V{aoai ...). Remark 
that this mapping is continuous. We will refer to a sequence for a finite or infinite word over 
S, and an observed sequence for a finite or infinite sequence over Sq. Clearly, the application 
of the mask function onto So of a sequence yields an observed sequence. 

The observable length of a run p denoted |p|o e N u {oo}, is the number of observable 
events that occur in it: |p|o = \<Jp\o- A signalling run is a finite run whose last event is 
observable. Signalling runs are precisely the relevant runs w.r.t. partial observation issues 
since each observable event provides an additional information about the execution to an 
external observer. Given states q,q' and an observed sequence a e Ej), we write q => q' if 
there is a signalling run from q to q' with observed sequence cr. 

In the sequel starting from the initial state goj SR denotes the set of signalling runs, and 
SR„ the set of signalling runs of observable length n. Since we assume that the POpLTS are 
convergent, for all n > 0, SR„ is equipped with a probability distribution defined by assigning 
measure P(p) to each p e SR„. Given p a finite or infinite run, and n < \p\o, Pin denotes the 



N. Bertrand and S. Haddad and E. Lefaucheux 


5 


signalling subrun of p of observable length n. For convenience, we consider the empty run go 
to be the single signalling run, of null length. 

2.3 Fault diagnosis for POpLTS 

To model the problem of fault diagnosis in POpLTS, we assume the event alphabet S contains 
a special event f e E called the fault. A run p is then said to be faulty if its associated 
sequence of events contains a fault, i.e. ap e S*fE“; otherwise it is correct. The set of faulty 
(resp. correct) runs is denoted F (resp. C). For n e N, we write F„ for the set of runs p such 
that Pin is faulty and C„ for the set of runs p such that pin is correct. By definition, for all 
n, O — Fn Lyi, F — IJneN and C — PlneN 

In order to reason about faults we partition sequences of observations into three subsets: 
an observed sequence ct € is surely correct if n \y{M.) £ (S \ f)“; it is surely 

faulty if n L“(A^) £ otherwise, it is ambiguous. For finite sequences, we need 

to rely on signalling runs: a finite observed sequence cr e E* is surely faulty (resp. surely 
correct) if for every signalling run p with V{ap) = a, p is faulty (resp. correct); otherwise 
it is ambiguous. A (finite signalling or infinite) run p is surely faulty (resp. surely correct, 
ambiguous) if V{p) is surely faulty (resp. surely correct, ambiguous). 

In order to specify various requirements for diagnosability we need to refine the notion of 
ambiguity. Let A/” be a POpLTS and n 6 N with n > 1. Then: 

H FAmboo (resp. CAmboo) is the set of infinite faulty (resp. correct) ambiguous runs of N\ 
H FAmb„ (resp. CAmb„) is the set of infinite runs of N whose signalling subrun of observable 
length n is faulty (resp. correct) and ambiguous; 

At this point it is interesting to look at the status of the different subsets of runs we have 
introduced with respect to the Borel hierarchy. The complementary sets Fn and C„ are 
unions of cylinders; so they are open (and by complementation) closed sets. The set of faulty 
(resp. correct) runs F (resp. C) is an open (resp. closed) set as a union (resp. intersection) 
of open (resp. closed) sets. The sets FAmb„ and CAmb„ are unions of cylinders; so they are 
open. The sets FAmboo and CAmboo may be defined as follows. Consider (Eq)“ and both 
equipped with the product topology. SameObs = {{p,p') \ V{p) = V{p')} is the inverse image 
by a continuous mapping of the closed set {(o’, cr) | a e E^}. Therefore SameObs is closed. 
Thus C X F n SameObs is a Borel set. The first and second projections are exactly CAmboo 
and FAmboo which establishes that these sets are analytic sets {i.e. continuous images of 
Borel sets). The set of analytic sets is a strict superset of Borel sets but every analytic set is 
still measurable w.r.t. the complete measure [12, 2H8 p.83]. 

In the context of finite POpLTS, we introduced four possible specifications of diagnosab¬ 
ility [3]. There are two discriminating criteria: whether the non ambiguity requirement holds 
for faulty runs only or for all runs, and whether ambiguity is defined at the infinite run level 
or for longer and longer finite signalling subruns. Let A/” be a POpLTS. Then: 

™ A/” is \F-diagnosable if P(FAmboo) = 0. 

™ A/” is \A-diagnosable if P(FAmboo w CAmboo) = 0. 

™ AA is FF-diagnosable if limsup^^oo IP(FAmb„) = 0- 
™ AA is FA-diagnosable if limsup„^oo P(FAmb„ a CAmb„) = 0. 

We recall in the next theorem all the implications that hold between these definitions. Missing 
implications do not hold, already for finite-state POpLTS. 

► Theorem 4 ([3]). Let M be a POpLTS. Then 
H AA FA-diagnosable => J\f \A-diagnosable and FF-diagnosable; 

H AA \A-diagnosable or FF-diagnosable => AA \F-diagnosable; 
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H If M is finitely branching, then M is \ f-diagnosable iff ff is ff-diagnosable. 

In order to illustrate the different kinds of diagnosability, we describe below some 
discriminating examples. 



U Figure 2 Left: a POpLTS that is IF-diagnosable but not lA-diagnosable. Right: a POpLTS that 
is lA-diagnosable but not FA-diagnosable. 


Consider the POpLTS Af on the left of Figure 2 where {n, f} is the set of unobservable 
events (represented by dashed arrows) and V is the identity over the other events. A faulty 
run will almost surely produce a 6 -event that cannot be mimicked by the single correct 
run. Thus this POpLTS is I F-diagnosable. The unique correct run p = qouqiaqi... has 
probability | and its corresponding observed sequence a“ is ambiguous. Thus the POpLTS 
is not lA-diagnosable. This simple example shows that, already for finite-state POpLTS, 
I F-diagnosability does not imply lA-diagnosability. 

Similarly, let us look at the POpLTS on the right of Figure 2 where {m, f} is the set of 
unobservable events and V is the identity over the other events. Any infinite faulty run will 
contain a 6 -event, and cannot be mimicked by a correct run, therefore FAmboo = 0. The 
two infinite correct runs have a‘^ as observed sequence, and cannot be mimicked by a faulty 
run, thus CAmbt^, = 0. As a consequence, this POpLTS is lA-diagnosable. Consider now 
the infinite correct run p = qouqiaqi .... It has probability |, and all its finite signalling 
subruns are ambiguous since their observed sequence is a", for some n € N. Thus for all 
n > 1, P(CAmb„) > I, so that this POpLTS is not FA-diagnosable. 

Characterisation of diagnosability 

The aim of this section is to establish “simple” characterisations of the diagnosability notions 
for a POpLTS Af = {{C,P),T,o,V) and more precisely to study whether one can express it 
as a Borel set B e B only depending on the underlying LTS C and the mask function V, such 
that almost surely a random run belongs to B if and only if Af is diagnosable. Furthermore 
if possible, one looks for a set B belonging to a low level of the Borel hierarchy. Observe 
that for all notions, this requires some machinery since the finite runs-based notions FF and 
FA are expressed by a family of Borel sets and the infinite runs-based notions IF and IA are 
expressed by a set which is not a priori a Borel set. 

Pursuing this goal, we introduce a language pathL for specifying Borel sets of runs. It is 
based on path formulae. A path formula a is a predicate over finite prefixes of runs. The 
(pseudo-)syntax of a formula of pathL is: 

0 ::= a I -.(/) I A ((i2 I Ofi 

where a is a path formula. In the sequel we use the standard shortcut afi = -• C> -•fi. 

A formula is evaluated at some position fc of a run p = qoaoqi .... The prefix p[0, k] of p 
is defined by / 9 [ 0 , A:] = qoaoqi ■ ■ - qk- The semantics of pathL is inductively defined by: 

H p. A: 1 = a if and only if a(p[0, fc]); 

H p, fc 1 = -10 if and only if p, fc 0 0 ; 
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H p, fc 1= </>! A (/)2 if and only p,k\= 4>i and p,k\= (j) 2 ] 

H p, fc 1= 0(f> if and only if there exists k' >k such that p, k' 1= (j). 

Finally p 1= 0 if and only if p, 0 1= (j). Due to the presence of path formulae (with no restriction) 
this language subsumes LTL and more generally any w-regular specification language. In 
order to reason about the probabilistic behaviour of a POpLTS, we introduce qualitative 
probabilistic formulae P'^p((()) with m 6 {<,>,=}, p 6 {0,1} and (f) 6 pathL. The semantics 
is obvious: N 1= if and only if P^^dp e fl | p |= (f)}) m p. Since pathL is closed by 

complementation the probabilistic formulae can be restricted to P"°(())) and P^°(())). 

Let us give some examples of path formulae. Given a finite run p = q^a^qi.. .qk, let f 
be defined by f(p) = true if = f for some index i. This path formula characterises the 
faulty finite runs. Let if be defined by if(p) = true if there exists a correct signalling run p' 
with V{p) = V{p'). Using the path formulae f and if, we exhibit a formula of pathL that 
characterises FF-diagnosability. 

► Proposition 5. Let N he a POpLTS. Then J\f is ¥¥-diagnosahle iff N t= P °(0 □ (f Aif)). 

Due to Theorem 4, in finitely-branching POpLTS the above characterisation also holds 
for IF-diagnosability. We also need the finitely-branching assumption in order to characterise 
lA-diagnosability. To this goal, let us introduce a more intricate path formula. For cr 6 S*, 
we define firstf (cr) by firstf (cr) = min{fc | 3p signalling run V{p) = a ^ pik is faulty) with the 
convention that min(0) = oo. Then the path formula 211 is defined by: 211(e) = false and 
2U((7oao . ..qn+i) = true if firstf(T’(goao • ■ -gn+i)) = firstf(P(goao ■ ■■qn)) < 

► Proposition 6. Let M he a finitely hranehing POpLTS. Then M is \A-diagnosahle iff 
A/'l=P=°(On (ilA2rr)). 



M Figure 3 An infinitely-branching lA-diagnosable POpLTS. 


The POpLTS of Figure 3 illustrates the necessity of the finitely-branching requirement in 
Proposition 6. {w,f} is the set of unobservable events and V is the identity over the other 
events. Observation h occurs in every infinite correct run, while the observed sequence of the 
single infinite faulty run is a‘^. This POpLTS is thus lA-diagnosable. However, it does not 
satisfy P"°(0 □ (if a 211)) since the unique infinite faulty run has probability | and satisfies 
□if. Indeed for every n € N, there is a correct signalling run with observed sequence a". 

Observe that the sets of runs specified by the characterisations of FF-diagnosability 
(On (f Ail)) and lA-diagnosability (On (ilA2Il)) are sets, i.e. countable unions of closed 
sets. Surprisingly, we show that such a characterisation is impossible for FA-diagnosability. 

► Proposition 7. There exists a finitely-hranehing LTS C and a mask funetion V sueh that 
for every Fa- set E of runs, there exists a POpLTS M = ((£, P), So, P) sueh that: 

H either J\f is fA-diagnosahle and Fj^{E) > 0; 

H or J\f is not fA-diagnosahle and ¥j^(E) = 0. 
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We conjecture that the previous impossibility result also holds for all Borel sets. The 
next proposition shows that a positive probability condition (instead of a null condition) 
may not exist whatever the Borel set. 

► Proposition 8. There exists a finitely-branching LTS C and a mask function V such that 
for every Borel set E of runs, there exists a POpLTS M = {{L,'P),Yio,V) such that: 

H either M is fA-diagnosable and ¥j\f{E) = 0; 

H or J\f is not fA-diagnosable and ¥j^{E) > 0. 

4 I Diagnosis for probabilistic pushdown automata 

We now turn to a concrete model for infinite-state POpLTS, namely the ones generated by 
probabilistic pushdown automata, and more specifically by probabilistic visibly pushdown 
automata. Our goal is to use the characterisations from the previous section to decide the 
diagnosability of POpLTS generated by partially observable probabilistic visibly pushdown 
automata (POpVPA). To do so, we face the difficulty that the Borel sets that characterise 
IF-, lA- and IF-diagnosability are not a priori regular, even in the finite branching case. 
Yet, for POpVPA, we circumvent this problem, and manage to specify these sets by pLTL 
formula on a determinisation of the model, tagged with the needed atomic propositions. The 
decidability of the qualitative model checking for recursive probabilistic systems [7] then 
yields the decidability of the above three diagnosability notions for POpVPA. 

4.1 Probabilistic visibly pushdown automata 

Among probabilistic infinite-state systems the ones generated by probabilistic pushdown 
automata [10, 7] support relevant decision procedures. Already in the non-probabilistic case, 
the subclass of visibly pushdown automata (VPA) [1] is more tractable than the general 
model. In VPA, the type of events determines whether the operation on the stack is a push, 
a pop, or possibly changes the top stack symbol, so that the languages defined by VPA enjoy 
most of the desirable properties regular languages have. 

► Definition 9. A probabilistic visibly pushdown automaton (pVPA) is a tuple A = (Q, S, P, 5, P) 
where: 

H Q is a finite set of control states with qq the initial state; 

B E is a finite alphabet of events, partitionned into local, push and pop events E = E^tuEjiiiEi,. 
H r is a finite alphabet of stack symbols including a set of bottom stack symbols Pi with 
initial symbol Iq e P±; 

H (5£(5xPxEx(5xP*is the set of transitions such that for every {q, 7 , a, q' ,w) e S, jicj < 2 , 
7 6 Pj^ implies w e Pi(P \ Pi)* and 7 ^ Pi implies ic e (P \ Pi)*; 

™ P is the transition probability function fulfilling for every q € Q and 7 e P: 

A transition t = {q,j,a,q',w) 6 (5 is said to be a local (resp. push, pop) transition if jwj = 1 
(resp. \w\ = 2, jicj = 0). We require that for every transition t = {q,j,a,q\w) eS, t is a. local 
(resp. push, pop) transition iff a is a local (resp. push, pop) event. 

The semantics of a pVPA is an infinite-state pLTS whose states are pairs (q, z) consisting 
of a control state and a stack contents. 

► Definition 10. A pVPA V = (Q,E,P, (5,P) defines a pLTS Mv = (Qvi (^Oj J-o), S, TvjPv) 
where: 

- gv = {( 9 ,^) | 9 €Qaz€Pi(PxPi)*}; 
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- TV = {{{q,zj),a,{q\zw)) I Z 7 erx(r nTx)* a ( 9 , 7 , a, g', w) € 5}; 

- For every {{q, zj), a, {q', zw)) € Ty, Py [((g, z-i),a, {q', zw))] = P[(q, 7 , a, q',w)]. 

► Example 11. Figure 4 gives an example of a pVPA. The event alphabet is composed 
of local events {serve, empty, reset}, a push event in and pop events [out, f, abort}. A 
transition t = {q,j,a,q',w) is represented by an edge from state q to state q' and labelled by 
P[t] ■'-f,a,w. The semantics of this pVPA is precisely the pLTS from Figure 1. Indeed, the 
stack alphabet consists of two letters F = { 7 , 10 } where the set of bottom stack symboll is 
Fi = {J-o}- Thus one can encode the stack using a counter that gives the number of 7 in the 
stack. For instance, in the pLTS from Figure 1 the configuration (gi,lo 7 "') of the pVPA 
corresponds to the state qin- 



M Figure 4 A pVPA generating the pLTS from Figure 1 with two finite runs. 


To define partially observable pVPA, we equip a pVPA with a mask function and 
require that only local events may be unobservable, and that pushes and pops can still be 
distinguished. Thus, the observed sequence of a signalling run of a POpVPA still provides 
the information about the height of the stack since it is equal to the difference of pushes and 
pops, plus one. 

► Definition 12. A partially observable pVPA (POpVPA) is a tuple (V,So,'P) consisting of 
a pVPA V equipped with a mapping 7^ : S ^ So u {e} such that: 

B So = So,^ B So,! B So,i, is the set of observations; 

H 7^(S^) £ So,^ u {ff}, 7^(S||) £ So,|| and 7^(S(,) £ So,!,. 

In the sequel, we may identify a POpVPA with the POpLTS it generates. In particular, 
the various concepts of diagnosability are lifted from POpLTS to POpVPA. 

4.2 Complexity of diagnosability for POpVPA 

To obtain an algorithm for the diagnosability of POpVPA, we follow the finite-state case 
approach [3]. First, we determinise POpVPA V into A{V), with the diagnosis objective in 
mind, building on the deterministic automaton recognising unambiguous sequences from [8]. 
We therefore introduce tags that reflect the category of runs (faulty or correct) given an 
observed sequence with a distinction between “old” and “young” faulty runs. It then suffices 
to check whether the characterisations hold on the synchronised product V x A(V) where V 
enlarges V by keeping track of a fault occurrence. To reduce to a decidable model checking 
question, we specify the Borel sets from Section 3 by LTL formulae. 
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Diagnosis-oriented determinisation. The determinisation of V (where probabilities are 
irrelevant for this transformation) into A{V) exploits some ideas of the original determinisation 
by Alur and Madhusudan [1], yet, it is customised to diagnosis. In particular, it uses tags that 
were first defined to construct a deterministic Biichi automaton recognising the unambiguous 
sequences of a finite LTS [ 8 ]. The complete definition of A{V) is postponed to Appendix B.l. 
We emphasise here some aspects of the construction and illustrate them on an example. 


^X _ I l,X,i;i l,X,/i ^X _ / 7,X,i;i 


±,U,(jo ’ ±,U,(}o J 




_ / 7,X,i;o \ uX _ t 7.x,qi i 7 X 
t 7,X,go J >'^1 t±,X.go-'’ °° 

7.x,/i 1 ^X _ f 7.X,gi 7.x, /i 1 


±,X,go ’ i.X.go J ’ 


- 7,U,go’ 7.U,go ^ ’ 


f 7.X,gi 1 

f 7.x,go-* 


Xe{U,W} 



(j-un |/±oAf9i io. 
|lj.o,U,go’ io, 





reset 




M Figure 5 The VPA A{V) associated with the POpVPA V of Figure 4 with two runs. 


States and stack symbols. The VPA A{V) tracks all runs with same observation in 
parallel memorising their status w.r.t. faults. More precisely to the current set of runs 
corresponds the symbol on the top of the stack which is a set of tuples where each tuple is 
written as a fraction ■ Let us describe the meaning of this tuple: 

H g is the current state of the run and 7 is the symbol on the top of its stack; 

H X 6 Tg = {U, V, W} is the status of the run: U for a correct run, V for a young faulty run 
and W for an old faulty run; 

H The denominator ( 7 “,X“,g“), is related to the configuration just after the last push event 
of the run: 7 “ is the stack symbol under the top symbol, while X~ is the status of the 
run reaching this configuration and q~ the state of this configuration. 

A priori, a single state run would be enough. However the simulation of a pop event in the 
original VPA is performed in two steps requiring some additional states that we explain later. 
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Illustration. The initial configuration of the VPA A{V) of Figure 5 (run, |{ ip’u’go }|) cor¬ 
responds to the empty run represented by a singleton. The denominator of bottom stack 
symbols is by convention (Iq, U,go) and is irrelevant for specifying the transitions of A{V). 
Tag updates. Let us explain how the tag X of an item of the current stack symbol 

is determined. If this item corresponds to a correct run then X = U. When, in a current state, 
after a transition of A(V) a (tracked) correct run becomes faulty in the next state, there are 
two cases. Either there was no tag W in (the numerators of items of) the top stack symbol 
of the current state then the run is tagged by W. Otherwise it is tagged by V meaning that 
it is a young faulty run. The tag V (young) becomes W (old) when, in the previous state, 
there was no tag W in the top stack symbol. A tag W is unchanged along the run. 

Push transitions. Given an observed push event o e from the control state run with 
top stack symbol bel, there is a looping push transition (run,bel,o,run,bel'bel'') in A(V) 
that encodes the possible signalling runs with observation o in V. More precisely for every 
transition sequence (q,a) =>■ (r,j3~j3) in V (i.e. a sequence of unobservable local events 
ending by an event e with T’(e) = o) and e bel one inserts x^’g- and 


(3”,Y,r‘ 


a” ,X~ 

in bel". The value of Y follows the rules of tag updates. 

Illustration. In Figure 5 several transitions correspond to the transition (qq, lo,in,qo, lol) 
of V, including (run,{ ^°''^’‘^° },in, run, { H il’u''^°o several transitions correspond 

to the transition iqo,l,in,qo,Jl) of V, including {run,{^A^j^in^ ^n,{^^^}{^(^}). 
Here, the specification of the tag updates is straightforward since it does not involve faulty 
runs. The runs represented in Figure 5 use these two transitions from the initial state. 


Local transitions. Given an observed local event o € from the control state run 
with top stack symbol bel, there is a looping local transitions (run, bel, o, run, bel’) in A(V) 
that encodes the possible signalling runs with observation o in V. More precisely for every 
transition sequence (q,a) => (r,P) in V (i.e. a sequence of unobservable local events ended 
by an event e with V(e) = o) and , e bel one inserts A^A _ in bel'. The value of Y 

follows the rules of tag updates. 

Illustration. In the VPA A(V) of Figure 5 there are several transitions corresponding to 
transition (q^, j, serve, qi,j) of V including (run, serve, run, The runs 

represented in Figure 5 use this transition. 

Pop transitions. Given an observed local event o € from the control state run with 
top stack symbol bel, the “pop operation” is performed by a sequence of two transitions: a 
pop transition labelled by o that keeps in the next state all the information needed by the 
next (local) transition labelled by e to move back to state run with a consistent stack symbol. 
Given an intermediate stack symbol, there is exactly one possible such transition. Thus 
despite these transitions, A(V) is still deterministic. The first transition (run,bel,o,£,e) 
in A(V) is specified as follows. The next state £ is a set of items of the following shape 
. More precisely for every transition sequence (q,a) => (r,e) in V (i.e. a sequence of 
unobservable local events ended by an event e with V(e) = o) and 6 bel one inserts 

q- in (-■ The value of Y follows the rules of tag updates. A transition (t, bel, £, run, bel') 
is specified as follows. For every ™ ^ ™ denominator of the 

first fraction and the numerator of the second fraction match), one inserts in bel'. 

Illustration. Let us describe how the pop event is performed by two transitions in the runs of 
the VPA of Figure 5 from the state reached after event serve. From qi with 7 as top of the 
stack there are two transitions whose observation is pop: (qi,j,out,qi,£) and ( 91 , 7 , f, /i,e). 
Thus starting from run with top stack symbol { reaches state £ = { 

The faulty run is tagged with W as there was no tag W in the former top stack symbol. In 
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the next configuration, the top stack symbol is So the transition labelled by e 

moves back to state run with updated top stack symbol { 7o’u'go ’ lo^’go 

Product VPA. We first define V whose set of states Q is a duplication of Q in correct 
states Qc and faulty states Qf. Given a transition of V starting from q leading to q', there 
is in V a transition starting from qf leading to q'f and a transition starting from qc leading 
either to q'c if the event is not f or to q'^ otherwise. We then construct V_ 4 (v) = V x A{V) 
the product automaton of V and A(V) synchronised on the alphabet of observed events Sq. 
The transitions of V labelled by unobservable events do not change the second component of 
the state and the transitions of A{V) labelled by e do not change the first component of the 
state. Due to the determinism of A(V), V^(v) has the same probabilistic behaviour as the 
one of V except that it memorises additional information along the run. More precisely, let p 
be a run of V, then p, a run of V_ 4 (v)) is obtained from p by following the same transitions 
and adding the single 0 transition firable after any pop transition. One immediately gets 

'Pv^(v)(p) =lPv(p)- 

Let us explain how to transform the paths formulae f, if and 22J into atomic propositions 
on the pairs {{q,run){‘y,b£l)) consisting of a control state of V^(v) together with a top 
stack contents. For path formula f, we define the corresponding atomic proposition Vf by 
iyf{{q,run){'y, bel)) = true if and only if g e Qf. Let bel £ (F x Tg x Q)^, we say that X 
occurs in bel if there exists £ bel. We define atomic propositions Vu and by: 

i'u{{q,run){f, bel)) = true if and only if U occurs in bel; and iywi{Q,i'un)("/, bel)) = true if 
and only if W occurs in bel. 

Given a run p of Va{v)^ write last(p) for the pair formed of the control state and top 
stack symbol in Va{v) after p. The atomic propositions Vf and Vu perfectly reflect the paths 
formula f and if, and Vw is eventually forever true if and only if 2II is. 

► Proposition 13. Let p be an infinite run ofV. Then: 

B For all keN, f{pik) ^ nf{\ast{pik)) and i/u(last(p|fc)); 

H p 1= O □ 2n 3AVfc > K. ^'.uj(last(p|fc)) = true. 

Thanks to the relationships between the paths formulae, and the atomic propositions, and 
using the characterisations from Section 3, we manage to reduce the FF-, IF- and lA-diagnosis 
to the model checking of a pLTL formula on the product VPA V^(v)- Model checking 
qualitative pLTL for probabilistic pushdown automata is doable in polynomial space in the 
size of the model [7]. In our case, V^(v) is exponential in the size of V. We thus obtain the 
decidability and a complexity upper-bound for the diagnosability problems for POpVPA. 

► Theorem 14. ff-diagnosability, \F-diagnosability and \A-diagnosability are decidable in 
EXPSPACE for POpVPA. 

Reducing the universality problem for VPA, which is known to be EXPTIME-complete [1], 
we obtain the EXPTIM E-hardness of all diagnosability variants for POpVPA. 

► Theorem 15. Diagnosability is EXPTIME-hard for POpVPA. 

The restriction to visibly pushdown automata is motivated by the unfeasibility of diagnosis 
for general probabilistic pushdown automata. The undecidability can be obtained by adapting 
the proof for diagnosis of non-probabilistic pushdown automata [11]. However, in order to 
show how robust the result is, we rather reduce from the Post Gorrespondence Problem 
and prove the undecidability of diagnosability for restricted classes of partially observable 
probabilistic pushdown automata, see Theorems 23 and 24 in Appendix B.4. 
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[~5l Conclusion 

We studied the diagnosability problem for infinite-state probabilistic systems, both from a 
semantical perspective, and from an algorithmic one when considering probabilistic visibly 
pushdown automata. A natural research aim is to reduce the complexity gap for the 
diagnosability of POpVPA (currently EXPTIME-hard and in EXPSPACE). We could also 
investigate the diagnosability problem for other probabilistic extensions infinite state systems, 
such as lossy channel systems or VASS. Another research direction would be to consider the 
fault diagnosis problem for continuous-time probabilistic models, starting with CTMC. 

- References - 

1 R. Alur and P. Madhusudan. Visibly pushdown languages. In Proc. STOC’04, pages 
202-211. ACM, 2004. 

2 N. Bertrand, E. Fabre, S. Haar, S. Haddad, and L. Helonet. Active diagnosis for probabil¬ 
istic systems. In Proc. FoSSaCS’14, volume 8412 of LNCS, pages 29-42. Springer, 2014. 

3 N. Bertrand, S. Haddad, and E. Lefancheux. Fonndation of diagnosis and predictability in 
probabilistic systems. In Proc. FSTTCS’14, volume 29 of LIPIcs, pages 417-429. Schloss 
Dagstuhl - Leibniz-Zentrum fuer Informatik, 2014. 

4 N. Bertrand, S. Haddad, and E. Lefancheux. Accurate approximate diagnosability of 
stochastic systems. In Proc. LATA’16, volume 9618 of LNCS, pages 549-561. Springer, 
2016. 

5 M. P. Cabasino, A. Gina, and C. Seatzn. Diagnosability of discrete-event systems nsing 
labeled Petri nets. IEEE Trans. Automation Science and Engineering, 11(1):144-153, 2014. 

6 K. Etessami and M. Yannakakis. Recnrsive Markov chains, stochastic grammars, and 
monotone systems of nonlinear equations. J. ACM, 56(1), 2009. 

7 K. Etessami and M. Yannakakis. Model checking of recnrsive probabilistic systems. ACM 
Trans. Computational Logic, 13(2):12, 2012. 

8 S. Haar, S. Haddad, T. Melliti, and S. Schwoon. Optimal constructions for active diagnosis. 
In Proc. FSTTCS’13, volume 24 of LIPIcs, pages 527-539. Schloss Dagstuhl - Leibniz- 
Zentrum fuer Informatik, 2013. 

9 S. Jiang, Z. Huang, V. Chandra, and R. Kumar. A polynomial algorithm for testing 
diagnosability of discrete-event systems. IEEE Trans. Automatic Control, 46(8):1318-1321, 
2001 . 

10 A. Kucera, J. Esparza, and R. Mayr. Model checking probabilistic pnshdown automata. 
Logical Methods in Computer Science, 2(1), 2006. 

11 C. Morvan and S. Pinchinat. Diagnosability of pushdown systems. In Proceedings of 
HVC’09, volume 6405 of LNCS, pages 21-33. Springer, 2009. 

12 Y. N. Moschovakis. Descriptive Set Theory. Mathematical Snrveys and Monographs. AMS, 
2009. 

13 M. Sampath, S. Lafortune, and D. Teneketzis. Active diagnosis of discrete-event systems. 
IEEE Trans. Automatic Control, 43(7):908-929, 1998. 

14 M. Sampath, R. Sengupta, S. Lafortnne, K. Sinnamohideen, and D. Teneketzis. Diagnos¬ 
ability of discrete-event systems. IEEE Trans. Automatic Control, 40(9):1555-1575, 1995. 

15 D. Thorsley and D. Teneketzis. Diagnosability of stochastic discrete-event systems. IEEE 
Trans. Automatic Control, 50(4):476-492, 2005. 





14 


Diagnosis in Infinite-State Probabilistic Systems (long version) 


A I Proofs for Section 3 

► Proposition 5. Let M he a POpLTS. Then M is ff-diagnosable iffJ\fi=F °(On(fAil)). 
Proof. Consider the set of fault-triggering runs: 


^ = {p = QoaoQi ■ ■ ■ ak-iQk \ Ofc-i = fAVi<fc-l, at + i} . 

Write if = {/9 e I O □ (f Ail)} for the set of runs we are interested in. We further define, for 
every p e'iK, Ep = {p' eLl \ p < p' Ap' |= nil) and for every n e N, = {p' eLl \ p < p' Ap' 1= □"ilj 
where p 1= a^cj) if for every fc < n, p,k\= cj). Observe that E = Ep and that Ep = 

Thus ?(£;) = Tpm^{Ep) and lim„^^ ^{E"^) = ^{Ep). 

• Assume first that P(if) > 0. Then, there exists p e IH such that P(ifp) > 0. By definition, 
for every n > \p\o P(FAmb„) > P(ifp). Thus, J\f is not FF-diagnosable. 

• Assume now that P(if) = 0. So, for every p e IH, P(ifp) = 0. Let us pick some £ > 0. Since 

F = UnsN Fn, there exists no such that for every n > no, P(F \ F„) < Let 91' = {p e 91 | 
|p|o < '^o}- Pick a finite subset 91" of 91' such that ZpeK'xiR"IF(p) - §■ Define K = |9l"|. 
Let m be such that for every n > ni and every p e 91", P(ifp) < Observe now that 
for every n > no, FAmb„ £ (F \ F„) u UpeSH'xK" E{p) u Upem" -E”. Thus, for every n > ni, 
P(FAmb„) < ^ + = e. Since e is arbitrary, Af is FF-diagnosable. •« 

► Proposition 6. Let M he a finitely branching POpLTS. Then J\f is \A-diagnosable iff 
Af^P=°(On (ilA2ir)). 

Proof. It is enough to show that p 6 0 is ambiguous if and only if p t= O □ (il a 2II). We focus 
below on correct runs; the case of faulty runs is similar and even simpler. 

• Let p 6 CAmboo. Since p is ambiguous, there exists a faulty run p' such that V{p') = V{p). 
Let ko be such that p}^^ is faulty. Thus for all k > ko, firstf('P(p;fc)) < ko and in addition it is 
non decreasing. So there exists some ki > ko such that for all k > ki, firstf('P(p|fe)) is constant. 
We thus obtain p 1= O □ 211. Moreover, since p t= □ il, we conclude that p 1= O □ (it a 211). 

• Let p be a correct run such that pl=On(ilA2Il). Thus there is a position ko such that for 
all k > ko, p,k \= 211. In particular, by definition of 211, for all k> ko, there is a finite signalling 
run p'(^^ such that V{p'^^^) = V{pik) and is faulty. Consider the tree of these runs 

by merging the common prefixes. This tree is finitely branching and infinite. By Konig’s 
lemma, it must admit an infinite branch, corresponding to a run p' with ’P(p') = ’P(p) and 
faulty. We deduce that p is ambiguous. ■* 

Let us recall some standard facts about Borel sets and measures. A set F is closed if and 
only if F = flneN On where 0„ is a union of cylinders defined by 0„ = {C'(p) | |p| = n a 3p' e 
F,p< p'}. Thus an F„ set F can be written as F = UmeN HneN where Om,,n is a union 
of cylinders whose associated paths have length n. Without loss of generality, the sequence 
of closed sets may be chosen as a non decreasing sequence. The measures we have defined 
in the core of the paper are regular. In particular, for every measurable set E such that 
P(F) > 0, there exists a closed set F Q E such that P(F) > 0. 

► Proposition 7. There exists a finitely-branching LTS C and a mask function V such that 
for every set E of runs, there exists a POpLTS M = ((£, P), So, F) such that: 

H either M is FA-diagnosable and ¥jy(E) > 0; 

H or Af is not FA-diagnosable and ¥jy{E) = 0. 

Proof. Consider the LTS C = {Q,qo,'E,T) defined as follows and let the mask function be 
defined by: V{u) = P(f) = e and V is the identity over the other events. 
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- Q = {/i,9/} u{(7i I i eN}; 

H S = {a,6,c,M,f}; 

~ T = {{qo,u,qf),{qo,u,qi),{qf,a,qf),{qf,b,qf),{qf,i,fi),{fi,bJi),{fi,cJi)} 

U {{qi,a,qi+i),{qi,b,qi+i)},>i. 



M Figure 6 A family of POpLTS whose underlying LTS has no appropriate characterisation of 
FA-diagnosability. 


We consider a family of POpLTS, represented in Figure 6, with underlying LTS C. For 
P = {Pn)n>i a sequence of probabilities, we define the POpLTS Mp = {{C,Pp),T,o,V) in 
which for every n > 1 the probability that b occurs from state qn is Pp(( 7 „, b, qn+i) = Pn, and 
all other probabilities are independent of p: Pp{qo,u,qf) = Pp{qo,u,qi) = Pp(/i,6,/i) = 
Pp(/i,c,/i) = i, Pp{qf,a,qf) = Pp(g/,6,q/) = PpiqjJJi) = 

Observe that lim„^oo ]P(FAmb„) = 0 and P(CAmb„_i) = Pn + Therefore, AAp is FA- 
diagnosable iff lim„—i-ooPn = 0. 

Let E be an arbitrary set. Pick some FA-diagnosable Mp i.e. with lim„—j-ooPn = 0. If 
Pp(i?) > 0 where Pp is the probability measure of this POpLTS, we are done. Assume thus 
that Pp(£’) = 0. In order to define a second POpLTS, via p', consider an infinite increasing 
sequence and let for n i {nj}j<i, p'^ = Pn and for n € {nj}j>i, p'^ = ^. Due to the 

sub-sequence p'^^ = |, Afp' is not FA-diagnosable. The sequence {nj}j<i depends on Pp and 
will be defined after some preliminary observations. 

Let F = {p \ qouqi < p}. Denoting Pp^ the probability measure of the second POpLTS, 
observe that Pp'(£’ \ F) = Pp(i?\F) = 0. Using the above discussion, the F„ set E n F = 
UmeNflnsNOm.n where for all m,n, Om,n is a disjoint union of cylinders C{p) with |p| = n, 
Om^n+l — Onri^n and Oni n — Onn,+\.n- Denote F^n — IjneNO/n,?! For all 7TZ, lim^_^oo Pp(OyTj 7 ^ ) — 
Pp(U n Fm) < Pp(U n F) = 0. 

• ni is chosen such that for all n > ni, < |. Observe now that for all nj, 

Pn = - = - Pn and t- Pn = - < t - Pn i -(1 - Pn ) 

By definition of Pp', since Om,n is a disjoint union of cylinders C{p) with \p\ = n, applying 
inductively the previous inequalities, for all n such that < n< n^+i (denoting ng = 0): 


Pp'(Om,n) < 


Pp(Om.n) 
2^ ni<j<fc Puj 


( 1 ) 


• Assume that we have chosen ni,... ,nk- Since lim„^oo Pp(Ofe,n) = 0, there exists Uk+i > Uk 
such that Pp(Ofc,nfc+i) ^ Tli<j<kPnj- We choose such an index. 

Equation 1 now implies that for all m< k, Pp'(Om,nfe+i) ^ Pp'(Ofe,nfc+i) ^ Thus for all 
m, Pp'(Fm) = liuik^^Vp'iOm^nk+i) = 0. Since EnF = UmeN-Fm, Pp'(FnF) = 0 and so 
Pp'(U) = 0. 
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► Proposition 8. There exists a finitely-branching LTS C and a mask function V such that 
for every Borel set E of runs, there exists a POpLTS M = ((>C,P),So,7^) such that: 

H either M is fA-diagnosable and Fj\f{E) = 0; 

H or Af is not fA-diagnosable and ¥j^{E) > 0. 

Proof. Consider the LTS C = {Q,qo,'E,T) defined as follows, and let the mask function be 
defined by: P(u) = P(f) = e and V is the identity over the other events. 

- Q = {fi,qf,qo}'->{qw\'we{a + b)*}; 

H S = {a,b,c,u,{}; 

j Qwa') 1 w&{ a+b)* ■ 



M Figure 7 Another family of POpLTS whose underlying LTS has no appropriate characterisation 
of FA-diagnosability. 


We consider a family of POpLTS, represented in Figure 7, with underlying LTS £, para- 
meterised by a mapping p : (a + 6)* ^ (0,1). Let Afp = {{C,Pp),T,o,'P) be the POpLTS such 
that the probability that b occurs from state is P{qw, b, qwb) = p{w), and all other probab¬ 
ilities are independent from p: Pp{qo,u,qf) = Pp{qo,u,qi) =Pp(/i,6,/i) = Pp(/i,c,/i) = b, 
Pp{qf,a,qf) = Pp{qf,b,qf) = Pp((?/,f,/i) = |. In the sequel, for convenience, we also write 
p{w, b) for p(w), and define p{w, a) = 1 - p(u>), so that P{q^,a, q^a) =p{w,a). 

Word w can be decomposed into letters w = tc[l]... w[n], and we give notations for factors: 
w[l,fc] = u>[l]... tc[fc] with the convention that r(;[l,0] = e. Finally we define Pp{w) = 
ni<fe<nP('“^[l) ^ “ l])'fi'[^])i as the probability to read w from Since lim„^t,o P(FAmb„) = 
0 and P(CAmb„_i) = E|u;|=n-i P('a', &) + we deduce that Afp is FA-diagnosable iff 
lini„.^oo Z|u,|=n-i P(w^, b) = 0. 

Let E be an arbitrary measurable set. Pick some POpLTS Afp which is FA-diagnosable, 
i.e. with lim„—X!|u,|=n-i P('a^i = 0. If PpC^l) = 0 where Pp is the probability of this 
POpLTS, we are done. Assume therefore that Pp(A) > 0. Let E = {p\ q^uq^ E p} be the set 
of runs starting with a u-transition to q^. Denoting Pp< the probability measure of any other 
POpLTS Np', observe that Pp'(i? ^ E) = Pp(A \ E). So, if Pp(£' n F) > 0, then by picking 
any non FA-diagnosable (>C,Pp'), we are done. So assume Pp(F \ E) = 0 which implies 
Pp(F n F) > 0. Using our recalls, there exists a closed set G Q E n E with Pp(G) > 0. 

If G = F then Pp<(G) = Pp(G) = |. In this case, we can therefore conclude by picking any 
non FA-diagnosable POpLTS Afp'. 

Assuming G E, since G is closed, there is some cylinder C{p) with p = qouqe.. .qw such 
that GnG(p) = 0. Then we define the POpLTS Afp' as the POpLTS Afp except that for every 
w <w' and every x € {a,b}, p'{w',x) = Thus for every n > |r(;|, ff\w'\=nP'^b) > . 

So Np' is not FA-diagnosable. On the other hand, Pp'(F n F) > Pp<(G) = Pp(G) >0. •< 
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B I Details and proofs for Section 4 


B.l Formal definitions 


Here we give formal definitions omitted in the core of the paper due to space constraints. 
More precisely given a POpVPA V, we define its estimate VPA A{V), its enlarged VPA V 
and their synchronised product. 

Let 6 {g, c, /} we write (q, 7 ) (q', w) with o € if when g = g (resp. c, /), there 

exists a general (resp. correct, faulty) run of transitions starting from ( 5 , 7 ) to {q',w) such 
that all transitions are unobservable except the last one labelled by e with V{e) = o. Let 
p be such a run then we also write {q,"t) {q',w) All transitions of such runs are local 

except the last one whose type depends on the type of o. 

► Definition 16. Given {V,V,'So) a POpVPA with V = P), its estimate VPA is 

the deterministic VPA A{V) = (Q®, So,P®, <5®) defined by: 

™ Q® = {run} IS ^ 0 ) jg gg^ gf states with initial state q^ = run] 

_ r® = \ 0 is the stack alphabet with set of bottom stack symbols P® = 2 ^"** \ 0 

where Init = | {X,q) e Tg x Q} and initial stack symbol ig = 

H The transition relation d® is defined as follows. 


local transitions {run, bel,o, run, bel') € 5® if: 

“ a^’u’q- ^ iff there exists e bel and {q,a) =>c {r,l3). 

_ If W occurs in bel, e bel' iff there exists € bel and {q, a) 

_ If W occurs in bel, 6 bel' iff 

(1) there exists € bel and {q,a) =^/ (r,/3) or 

( 2 ) there exists € bel and {q,a) {r,P)- 

_ If W does not occur in bel, 6 bel' iff 

(1) there exists e bel and {q,a) =^/ (r,/?) or 

( 2 ) there exists € bel and {q,a) {r,P)- 

push transitions {run, bel,o, run, bel'bel") e 5® if: 


6 bel' and 6 

,U,r 
/3~,W,i 


a. M,q 0' 

If W occurs in bel 


bel" iff there exists € bel and {q,a) 

ot .U.o •' 


'.X.g- 


bel' and e 

p y\/,r 


P,q- 

bel" iff 


there exists e bel and {q,a) =>g {r,/3 j3). 

_ If W occurs in bel, ^ A'" e bel' and e bel" iff 

(1) there exists € bel and {q,a) {r,P~/3) or 

(2) there exists € bel and {q,a) =>g {r,l3~P). 

_ If W does not occur in bel, A’’'! € bel' and 6 bel" iff 

’ OL ,X,g p ,\N,r 


(1) there exists e bel and {q,a) =^/ {r,l3 P) or 

(2) there exists € bel and {q,a) (r,/3“/3). 

pop transitions {run, bel,o,£,e) € (i® with £ € Q® \ {run} if: 


U,r 


a.~ .\J,q~ 


^ ^ iff ® (9’ “) (A e)• 


■g (a/3)- 


c {r,P P). 


If W occurs in bel, AA ^ € .£ iff there exists e bel and {q, a) =^„ (r, e). 

’ Q! .X,g a ,X,q / y \ ’ / 

_ If W occurs in bel, —— e i iS 

’ Q!~,X,q'~ 

(1) there exists A e bel and {q,a) =>f {r,e) or 

( 2 ) there exists A’x q- ® (’’)£)• 
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■ If W does not occur in bel, _ e £ iff 

( 1 ) there exists € hel and ( 9 , 0 ) =^/ (r,e) or 

(2) there exists 6 bel and {q,a) =^g (r,/3“/3). 

e-transitions (£, bel,e, run, bel') e 6^ if: 

6 bel' iff there exists „ 6 bel and ^ € i. 

ol ,q OL ,X ,q OL,^,q 

While ^(V) contains e-transitions it is deterministic: from any configuration, either a 
single e-transition is enabled or for all event o, there is at most one o-transition enabled. We 
say that a configuration is stable if its associated state is run. 

Illustration. Let us look at the run given in the example of Figure 5. It starts in the initial 

configuration {run, |{ }|) which represents the empty run. 

From qo there exists only one path of observation in the POpVPA. As this path is correct, 

I jydWo-j 

by reading in on the estimate VPA we reach {run, 


J-o,U,(jo 
f ip.U.go 1 
I ±o,U,go -* 


). The new element of the stack 


{ u } signifies that the real stack has head 7 and is in go after a correct run, moreover 
the run entered go when it pushed this 7 and it does not have a second non-terminal element 

f 7,U,go 1 
^ ^.U.On J 

in our stack. Reading a second in is still doable by a single run, we reach {run. 


7.U,9o 

r 7 .U .90 1 

^ I n .IJ .t7n J 


) 


' J-o.U.go 
r lo,U.i?o 1 
^ J-o A,go 

which modifies one information compared to before: we know from the bottom part of the 
head stack that the stack has at least a second 7 . 

Reading a serve then is possible as there exists a correct signalling run from go to gi 
with only observable serve. The estimate VPA modifies the head stack so as to represent 
that the run we follow is now in gi but without modifying anything else. 

Reading a pop event raises a complication: from gi with head of stack 7 , reading a pop 
can be done by a correct run staying in gi or by a faulty run going in /i. To represent 
this and the popping of the stack, we go in two steps. In the first step, we go to the state 
^ ^ keeps the information of the two possibilities of current configuration 

and we pop the stack. In the second step, we deterministicaly read an e transition that 
transfer this information from the state to the stack. In order to transfer the information, 
the estimate VPA checks which of the current possible runs (represented by and ) 
corresponds to each of the new head of stack. This is done by comparing the bottom part of 
the run with the top part of the head of stack, here 7 , U,go in every cases. Reading a second 
pop realises a similar process reaching {run, |{ }|)■ empty would lead to 

{run, |{}|) as there is a correct run from gi to go labelled by empty but no run from 
/i with such label. Conversely a reset can not be read from gi but it can be read from /i, 
thus we reach (run, 

The estimate VPA manages information in order to evaluate Vu and In order to 
evaluate Vf, the enlarged POpVPA keeps within its states the status (correct/faulty) of the 
run. 


► Definition 17. Let V = ((5,S,r,(5, P) be a pVPA. Then the pVPA V = (Q,S,r,5, P) is 
defined by: 

™ Q = Qc^ Qf where Qc = {gc | q s Q} and Qf = {g/ | g e <5} with initial state go,cl 

H For all {q,^,a,q',w) 6 5 with a 7 f and all g e {c,/}, {qg,^,a,q'g,w) 6 5] 

■ For all (g, 7 , f , g', w) ^ 5 and all g € {c, /}, (gg, 7 , f , q'f,w) & 5; 

- For all {qg,-^,a,q'g,,w) 6 5, P(gg, 7 ,a,gj,,, w) = P(g, 7 ,a,g',u;). 
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We now define the product V^(v) between V and ^(V) that keeps all the information we 
need along a run. 

► Definition 18. Given {V,V,T,o) a. POpVPA with V = (Q,S,r,5, P) and A{V) = run, Eo,r®,(5®), 
their synchronised product is the pVPA V^(v) = S u {e}, P^, P^) where: 

B = Q X is the set of control states with initial state = {qo,c, run); 

H = r X r® is the stack alphabet with Pi x P® the set of bottom stack symbols and 

symbol; 

B The transition relation consists of: 

local transitions. 

• For all (g, 7 ,a,g', 7 ') € S with a unobservable and bel € P®, 
{{q,run),{j,bel),a,{q',run),{j',bel)) € 5-^; 

• For all (g, 7 ,a,g', 7 ') 6 S and {run, bel, o, run, bel') 6 (5® with V{a) = o; 
{{q,run),{j,bel),a,{q',run),{j',bel'y) 6 5^; 

• For all {£, bel, e, run, bel') € (5®, q^Q and 7 e F, 
iiqA),{l, bel),e, {q, run), ( 7 , bel')) 6 S^; 

push transitions. 

• For all {q,j,a,q','j'^") e S and {run, bel, o, run, bel'bel") e S" with V{a) = o; 

{{q, run),{'f, bel), a, (g', ran), ( 7 ', bel'){i', bel")) e S-^; 

pop transitions. 

• For all {q,j,a,q',e) e S and {run,bel,o,£,e) e 5" with V{a) = o; 

{{q, ran), ( 7 , bel), a, {q',£),e) e 

H The transition probability function P"^ is defined by: 

P-^((( 7 , run), ( 7 , bel), a, {q', run), ( 7 ', bel')) = P(g, 7 , a, q', 7 '); 

P-^((g, run), ( 7 , bel), a, {q', run), ( 7 ', bel'){i', bel")) = P(q, 7 , a, q',H'); 

P-^(((?, run), ( 7 , bel), a, {q',£),e) = P{q, 7 , a, q', e); 

- for ^ € Q® \ {run},P^{{q,£), ( 7 , bel),Q, (q, run), ( 7 , bel')) = 1. 


Illustration. The product POpVPA contains the current run of the POpVPA, information 
on the correctness of the run and the information given by the estimate POpVPA. If we 
look at the faulty run given in the example of Figure 4, after reading in, we are in state 

{qo^c,run) meaning our real state is qo, it was reached by a correct run and our estimate 

f y.u.go 1 

^ In.U.On J 


VPA is in state run, the head of stack is ( 7 , 


), meaning our real head is 7 and the 


- ±o.U,(jo - 
f io,U,go 1 
t io,U,go 

rest is the head of the estimate VPA. If we follow the faulty run until after the first pop, we 
reach the state (/i./, thus in fi with a faulty run and the estimate 

VPA is in one of the temporary states. In order to leave this state, we read a © which leads 
to the state {fij,run). © is an event affecting only the part of the POpVPA corresponding 
to the estimate VPA, making it realises the £ transition. 

Given a finite run p of V, we inductively define the run p of V_ 4 (v) as follows. First 
(qoAo) = (q^A'o)- Let p of length n > 1, a € E and 9 e Q and 71 ,... , 7 ;^ € F such that 
p = p'a(g, 7 i.. . 7 / 1 ). If a St then p = p'a{{qg,run),{^i,beli )... {^h,bAh)) where g = c iff 
p is correct and {run, beli ... belt) is the configuration reached by V{p) in A{V). If a € S|, 
then p = p'a{{qg,£), {ji,beli )... {jh, belt)) Q {{qg,run), {"fi,beli)... {'^h-iMlh-i){lh,bA'h)) 
where 5 = c iff p is correct, {£,beli .. .belu) is the configuration reached by V{p) in A{V) 
and {run, bell... belh-ibel'j,) is the single next configuration reached by an e transition. As 
previously observed, P(p) = P(p). 
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B.2 Decidability of diagnosability for POpVPA 


In order to prove decidability of diagnosability for a POpVPA V, one wants to check whether 
the formulae characterising diagnosability hold on V. To do so, we transform the pathL 
formulae of Section 3 into pLTL properties that are checked on V^(v)- These pathL formulae 
use three paths formulae f, il and 211. In the core of the paper, we explained how to define 
alternative pLTL formulae, relying on atomic propositions and that only depend 

on the current control state and top of stack symbol of V^(v)- Proposition 19 links runs of 
V and observed sequences of A{V) and Proposition 13 establishes the correctness of the v^s 
with respect to the paths formulae f, il and 211 . 


► Proposition 19. Let a he an observed sequence of A{V) and p* he its corresponding finite 
run with successive stable configurations {run, Wq) ■ ■ ■ (run, Wn) ■ Let Wn = beli ... belh and 
for i <n, bel^^^ be the top stack symbol of Wi. Then: 


For all —— g belh, there exists a sequence ( 


7i,Xi,gi 


)o<i<h such that for all i, 

7 1 X 1 g 1 ^ and a signalling run p of V such that V{p) = a that reaches configuration 
{qh,li ■ ■ - Ih)- In addition: 

H if Xh = U then p may be chosen correct; 

H if Xh + U then p may be chosen faulty; 

H (f Xft = W then there exists 0 < k < n, such that pik is faulty and W does not occur in 
bel^^-^\ 

• Conversely, let p he a signalling run of V such that V{p) = a reaching configuration 
{qh,li ■ ■ -Ih), there exists a sequence ,^ )o<i<h such that for all i, ^ ^ ^ belt. 

In addition: 

H if p is correct then Xj, = U; 

H if p is faulty then Xh + U; 

H if there exists 0 < k < n, such that pik is faulty and W does not occur in bel^^~^^ then 
Xh = W. 


Proof. We prove it by induction on |cr|. The basis case is straightforward. For the inductive 
step, we only detail the most involved case: (T[n] e For the properties related to tags, we 
only detail the ones related to W. Denote a' = a[l]... cr[n - 1] and Wn-i = bel[... bel'f^bel'f,^^. 


• Let 


7fe.Xfe,gfe 


6 belh- By construction, there exists e bel'f,^^ with 7 ^ = jh, 


a signalling run ^ (%,e) with proj{p") = cr[n], e where 

{lh-i,'>^'h-i>Qh-i) = {'lh-i,'>^h^i,qh^i) and Xh is obtained by updating w.r.t. and 

p”. In particular if X/j = W then 

(1) X'= W, or 

(2) W does not occurs in bel'^^^ and (a) XJ^^^ = V or (b) XJ^^^ = U and p" is faulty. 

By inductive hypothesis, there exists a sequence ( , — )o<i<h such that for all i, 

7i_i ^Qi-i 

, e beh and a signalling run p' of V such that V{p') = a' reaching configuration 

'^i-1 ’^i-1 

{qh+i,'Ji ■ ■. 7 ^+i)- Consider the signalling run p = p'p"', it reaches configuration {qh,7i ■ ■ ■ I'h)- 
Since for all i<h, beli = beh, the sequence ( , — )o<i<h and the run p are appropriate. 

The three additional properties follow from the rules of tag updates. 

In particular, if Xh = W, then 

o the assertion ( 1 ) holds and then the property comes from the inductive hypothesis, or 
o the assertion (2) holds which implies that W does not occur in bel'/,^^ and p is faulty. 

• Let p be a signalling run of V such that V{p) = a which reaches configuration (g/i, 71 ... 7 ^,). 

Let us write p = pin-ip” with ( 9 ^+ 1 , 7 ^+ 1 ) ^ {qhtE)- By the inductive hypothesis, there 
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exists a sequence (—)o<i<?i+i such that for all i, y—- 6 bel[ and for all i < h, 
7 ' = ji- By construction, , — g belt for some X^. Since bek = bel', for all i < h, we 

'^h-1 '^h-1 '^h~l 

obtain the required sequence of items. 

The three additional properties follow from the rules of tag updates. In particular, assume 
there exists 0 < k <n, such that p^k is faulty and W does not occur in bel^~^. 
o If pin-i is correct then, as p is faulty, p” is faulty and W does not occur in bel'^~^ = bel'^^^. 
So by construction Xh = \N. 
o If pin-i is faulty then 

B either = W and by construction X/j = W, 

B or Xjj^^ = V. By induction hypothesis there does not exist 0 < fc < n - 1, such that p^k is 
faulty and W does not occur in bel^~^. So W does not occur in bel^~^ = bel'j^^^. Therefore 
Xh = W. 


► Proposition 13. Let p be an infinite run ofV. Then: 

■ For all keN, f{pik) ^ i'f{\ast{pik)) and il(p|fe) j/„(last(p|fe)); 

H p 1= O □ 211 <=> 3K'ik > K. t'u,(last(p;fc)) = true. 

Proof. First, remark that f and Vf obviously coincide: they both express that a fault 
occurred. 

To prove the second item, about il and we use the link from between observed sequences 
and the tag U in V_ 4 (v)- Let a be an observed sequence triggered by a run of V. Then bel^ is 
the top stack symbol of the stable configuration in A{V) reached by the run accepting cr (so 
ending by an e-transition if the last event is a pop event). Due to Proposition 19, U occurs 
in bel^ iff there is a correct signalling run of V with observed sequence cr. According to the 
definition of we thus deduce that for any finite signalling run p of V, ;/u(last(p)) = true iff 
il(p) = true. 

We now establish the link between 211 and To show the left-to-right implication, let 
pen and Kq eN he such that p, ATq ^ ^211. By definition of 211, firstf (7^(p|fc)) is constant 
and bounded by Kq for k > Kq. For all fc e N, let belk be the top stack symbol reached in 
A{V) after reading the observed sequence V{pik)- If for all k > Kq, W occurs in belk, then 
for all k > Kq, rc.„,(last(p|jt)) = true. Otherwise there exists Ki > Kq such that W does not 
occur in belxi- Let k > Ki, as firstf('P(p|fc)) < Kq, there exists a faulty run p' of V_ 4 (v) such 
that V{p') = 'P{pin) and pj^ is faulty. W does not occur in belKi and p\xi+i faulty. Thus 
by Proposition 19, W occurs in belk- Therefore for all n > Ki, ^'u,(last(p|„)) = true. 

Let us show the right-to-left implication. Let p € O and AT 6 N be such that for all k > K, 
r'u,(last(p|fe)) = true. By definition of Vw for all k > K,\N occurs in belk (defined as above). Let 
fc > if, by Proposition 19, there exists a run p' of Va(v) such that V{p') = 'P{pik) and there 
exists n< k such that pj^ is faulty and W does not occur in beln-i- Thus n< K. Therefore 
for all k> K, firstf('P(p;fc)) < K. Since beyond K first! is bounded, it is non decreasing and 
then eventually constant. Let K' such that for all k > K' , first!('P(p|/j)) = firstf(P(pjfc_i)). 
So p, if' 1 = □21J and thus p 1 = O □ 2II. •* 

We extend Vf, Vu and over configurations c/ = {{q,£),w)) with I + run by Vficf) = 
Vu{cf) = I'wicf) = true. 

► Theorem 14. ff-diagnosability, \f-diagnosability and \A-diagnosability are decidable in 
EXPSPACE for POpVPA. 
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Proof. The above lemmas allows us to derive pLTL characterisations of diagnosability for 
POpVPA. Namely, for V a POpVPA, as V and V^(v) have the same probabilistic behaviour, 
™ V is FF-diagnosable iff Vj^(y) l= P"°(0 □ {vf a 
™ V is lA-diagnosable iff V^(v) l= P "°(0 □ {I'u a I'w))- 

Moreover, since the POpLTS generated by POpPDA are finitely-branching, IF-diagnosability 
coincides with FF-diagnosability [3] (See also 4). The two above qualitative pLTL formulae 
can be checked on general probabilistic pushdown automata (beyond visibly pushdown ones) 
thanks to [6]. More precisely, one can transform V^(v) into a recursive Markov chain (the 
transformation is linear) [7]. Then, the model checking of qualitative pLTL on recursive 
Markov chains is doable in PSPACE in the size of the Recursive Markov Chain and EXPTIME 
in the size of the formulae [6]. In our case, the product VPA V_ 4 (v) is exponential in the 
size of V and the size of the formulae is constant. This yields an EXPSPACE algorithm for 
checking diagnosability of POpVPA. ■* 

B.3 EXPTIME-hardness of the diagnosability for POpVPA 

We prove here Theorem 15, stating the EXPTIME-hardness of diagnosability for POpVPA. 
Let us restate it below more precisely. 

► Theorem 20. ff-diagnosability, V/K-diagnosability and \A-diagnosability are EXPTIME-Ziard 
for POpVPA. 

Proof. Let us start with FF-diagnosability. The proof is by reduction from the universality 
problem for VPA, which is known to be EXPTIM E-hard [1]. 

From a VPA V = (Q,S,r,(5) and a subset of accepting control states Q/ £ Q, we build a 
pVPA V' = (Q',S',r', V,P') as follows: 

H Q' = Q LI {/o, /i,, ^Q, (/I,} and is the initial state; 

. S'= Eiii{f,M,b,|]}; 

. r' = rB{R} andr;^ = ri; 

H Writing S^^, resp. and di, for the set of local resp. push and pop transitions of V, S' 
consists of the following transitions: 

local (5^ u {((7o,lo,u,lo,go),(go,lo,f,lo,/o),(/o,7,ll,7,/0 I 76 ru {iq}} 
u {(g,7,ll>7,9b) l9eQ/,7 6 ru{lo}} 
u {(/o,7,a,7,/o) |a 6 V^, 76 {R,io}} 

U {(9b: J-O, [], lo, 9o), (/b, J- 0 ,1], J-O, /o)}; 
push (5, u {(/o, 7 ,a, 7 R,/o) I a€ S,, 7 € {R,io}}; 

pop <5i,u {(/o,R,a,e,/o) I aeSju {(/i,,R, b,e, /b)} u {(gi,, 7 , b,e,gb) | 7 e P}; 

H P' is such that for every 7 € P, P'(/o,7, [],7,/b) = and assigns arbitrary positive 
probabilities to the other transitions in S'. 

We further consider the POpVPA (V',So,'P) with Sq = Su{b,[]} and the masking function 
satisfies 'P(u) = 'P(f) = e and P(x) = x for any other event x 6 S'. This construction is 
illustrated in Figure 8. The figure uses the following shortcuts: a\, € Sj,, 6 S^, oj € Sj, 7 e P, 
7 ' € {B, lo} and z 6 P \ {Iq}. 

The correct observed sequences in (V', So, V) are either of the form wx \\\)^^ \\W 2 . ■ ■\\ b^"'' \\ Wn 
or of the form wi \\\)^^ \\W 2 . ■ ■\\ Wn-i I] b™- In these decompositions, Wi, for j < n, is a sequence 
corresponding to a run of V starting in go and ending in some accepting state qf € Qf, ki is 
the number of elements in the stack after reading Wi in V and also in V' (apart from the 
bottom stack symbol Iq), Wn is the sequence associated to a run of V starting in go> and m 
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M Figure 8 A POpVPA for the EXPTIME-hardness of FF-diagnosability. 


is at most the number of elements in the stack after reading Wn-i in V. Note that ki only 
depends on Wi, and does not depend on the exact run over Wi, since V is a VPA. 

Now, the faulty observed sequences in (V', So, 7^) are either of the form \\W 2 ■ ■ ■\\ \\ Wn 

or of the form \\W 2 ■ ■ ■\\ Wn-i 1] b"*- In these decompositions, WieT,*, ki is the size of 

the stack in V' (apart from the bottom stack symbol Iq) after reading Wi and m is at most 
the number of elements in the stack of V' after reading Wn-i- 

Let us show that V is not universal if and only if (V',So,'P) is FF-diagnosable. 

First assume that V is not universal. Then there exists a word ic € E* such that no run of V 
reading w ends in an accepting state qf. However, the observed sequence of any faulty run 
almost-surely contains the factor \\w\\. Indeed, faulty runs almost surely visit infinitely often 
the configuration (/i,,lo), and from there, the probability A to read |:]?n|:] is positive. Let p be 
an infinite faulty run. Its observed sequence is of the form V{p) = wi I] b^^ \\W 2 \\\)^^ \\W 3 ... 
with ki < jwil for every i. If there exists i < n such that Wi = w then p is surely faulty, 
since it has no corresponding correct run. The latter statement can be refined. For n > |r(;|, 
if, for every i < n, IwiI < n and there exists i < n such that Wi = w then Pi 2 n^+n is surely 
faulty. Indeed, \wi \\\>^' \ < 2n + 1, w occurs at the latest for i = n, and once it occurs the 
prefix is surely faulty. Let us therefore consider faulty runs that do not satisfy this property. 
We let Avoids = {p e F | V{p) = \\W 2 \\\/^^ \\W 3 -- - a (Vi <nwi + w\/3i<n \wi\ > n)}. 

By construction, FAmb 2 „ 2 +„ £ Avoids. Moreover, using standard union-sum inequalities, 
P(Avoid„) < (1 - A)" + ^ (recall that A is the probability to read \\ w [] from (/o, lo))- Thus 
lim„^oo P(Avoid„) = 0 and hence lim„^oo P(FAmb„) = 0 so that (V',Eo,7^) is FF-diagnosable. 
Assume now that V is universal. Let p be an infinite surely faulty run of (V',So,'P). We 
write p' for the greatest ambiguous prefix of p and a 6 So u {I], b} such that p'a is again a 
prefix of p. Observe that a cannot be b since the number of b’s between two Ij’s, whether on 
the left or right-hand-side of V', is entirely determined by the word of S* read before the 
first \^. For the same reason, if a = [j, V{p') ends with a word of S* (z.e. the number of [j’s in 
V{p') is even). Let w be the greatest suffix of V{p') contained in S*. If a = [j, we deduce 
that there is no run starting in qq with observed sequence w and ending in an accepting state 
of V. Therefore, V is not universal. Similarly, if a e Sq, then there is no run starting in go 
and with observed sequence wa. In that case also, V is not universal. We hence conclude 
that there is no infinite surely faulty run in (V^Eo,7^). As the probability to generate faulty 
runs is positive, this implies that (V',So,'P) is not IF-diagnosable. Now, IF-diagnosability 
is equivalent to FF-diagnosability for finitely branching POpLTS (see Theorem 4), and so 
(V',So,7^) is not FF-diagnosable. 

Let us now argue for the EXPTIM E-hardness of FA-diagnosability and lA-diagnosability. 
From the VPA V = ((3,E,r,5) and pVPA V' = (Q', S',F',(5') defined above, we construct a 
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pVPA V" = (Q",S",r", such that 

H Q" = Q' u {qc} and Qq is the initial state; 

. S" = Su{f,M,t|,a}; 

_ r" = T; 

- S'' = S'u {{q,a,-f,qc)\jeTu{io},qeQu { 9 ^}}; 

H P" assigns arbitrary positive probabilities to transitions in S”. 

We further consider the POpVPA (V", So,’^) with Sq = S" \ {f, m}, and the masking function 
satisfies 'P(f) = 'P{u) = e and 'P{x) = x for any other event x. The construction is illustrated 
in Figure 9, where we use the shortcuts: 0 |, e Si,, e S^, aj e Sj, 7 e P, 7 ' 6 and 

z € r \ {lo}- 



M Figure 9 A POpVPA for EXPTIM E-hardness of FA-diagnosability and lA-diagnosability. 


V" is a slight modification of V': from any state of V (accepting or not), reading the new 
letter a leads to the sink state qc- As a consequence, for any correct run of (V", So, V), there is 
a positive probability at each step to perform event a and become surely correct. This implies 
lim„^oo P(CAmb„)„gN = 0. Observe that the above proof for V' also applies to V": V is not 
universal if and only if (V",So,'P) is FF-diagnosable. Now, since lim^^oo P(CAmb„)„gN = 0, 
FF-diagnosability, FA-diagnosability and lA-diagnosability coincide for (V",So,'P). We 
conclude that V is not universal if and only if (V",So,'P) is diagnosable (for any notion of 
diagnosability). ■* 

B.4 Undecidability of diagnosability for POpPDA 

As stated in the core of the paper, diagnosability is undecidable for partially observable 
probabilistic pushdown automata (POpPDA). Let us first give the definition of pPDA and 
POpPDA. Contrary to VPA, in PDA, the action does not determine the operation (push, 
pop, local) on the stack. 

► Definition 21. A probabilistic pushdown automaton (pPDA) is a tuple A= (Q,E,r,(5, P) 
where: 

H Q is a finite set of control states with qo the initial state; 

H S is a finite alphabet of events; 

H P is a finite alphabet of stack symbols including a set of bottom stack symbols Pi with 
initial symbol Iq e r±; 

H (^£QxrxI]xQxr*is the set of transitions such that for every (g, 7 , a, q, w) € 6 , |iy| < 2 , 
7 6 Pj^ implies w € ri(r \ Pi)* and 7 ^ Pi implies rc 6 (P \ Pi)*; 
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H P is the transition probability function fulfilling for every q ^ Q and 7 e F: 

Z P[(9,7,a,9','w)] = 1 . 

► Definition 22. A partially observable pPDA (POpPDA) is a tuple (A, SojP) consisting of 
a pPDA A equipped with a mapping P ; S Sq u {e} where is the set of observations. 

The undecidability of diagnosability for POpPDA can be derived from the undecidability 
of diagnosability for non-probabilistic PDA [11]. However, to show how robust the result 
is, we refine the statement into Theorems 23 and 24: undecidability already holds for two 
(incomparable) subclasses of POpPDA with restriction on what is observable and on the 
number of phases of any run. A phase is a portion of run in which the stack either never 
decreases or never increases. 

► Theorem 23. The diagnosability problems are undecidable for POpPDA even when (1) the 
top of the stack is not updated, (2) every event labelling a push transition is fully observable 
and corresponds to the pushed symbol, and (3) every run consists of at most two phases. 

Proof. The proof is by reduction from the Post correspondence problem (POP). An instance 
of POP is given by an integer n 6 N and two families of non-empty words {vi}i<n and {wi}i<n 
on the alphabet {a,b}. The following question is undecidable: does there exist k> 0 and 
ii,...ik^{l,...,n} such that Wi^ ...Wi^,= 

In this proof, we let li (resp. mi) be the length of Vi (resp. Wi). Also, given a word w 
and k < jruj we use w[k] to denote the fc‘^-letter of w. 

From an instance {n,{vi}i<n,{wi}i<n) of PCP, we build a pPDA A = ((5,S,r,5, P) as 
follows: 

- Q = {qo,qc,qs,fs}'->{q'f \ l<i<nA<k<ei}u{fjf \ l<i<nA<k< mi] ; 

. E = {l,...,n,|:],u,r,f,a,&}; 

. r = {l,...,n,lo} with P^ = {lo}; 

H 5 consists of the following transitions: 

{(go, J-o, X, loa;, gc) | 1 < a: < n} 
u {{qc,x,y,xy,qc) \l<x,y<n} 

u {{q’f,z,v,[k],z,q^^^) I 1 < i < n,l < fc< 7 ,z€ {lo,l,...,n}} 
u {ifi>z,Wi[k],z,fi^'^) I l<i<n,l<fc<mi,z€{io,l,...,n}} 
u {{q^%z,Vi[£^],z,qs) I l<i<n,z€{lo,l,...,n}} 

u I ^mn,z&{loA,---,n}} 

u {{qs,x,r,e,q],) | 1 < a: < n} 
u {{fs,x,r,e,ff) I l<x<n} 
u {{qc,x,u,x,qs),{qc,x,f,x,fs) | 1 < a: < n} 
u {(gs, io, 1], J-o, gs), (/s, J-o, 1], J-o, fs)}- 
H P assigns arbitrary positive probabilities to transitions in (5: 

P{qA,a,q',w) > 0 <» (g, 7 ,a,g','u;) € 6 and E(q, 7 .a.q'.u,) 65 ?[(<?,7,a, J^)] = 1- 
We further consider the POpPDA {A, So, 'P) with So = E \ {r, it, f}, and the masking function 
satisfies ’P(it) = V{r) = V{{) = e and V{x) = x for any other event x. This POpPDA is 
represented in Figure 10. 

Let us prove that the instance of the PCP is positive if and only if the POpPDA is IF-, 
I A- and FA-diagnosable. 

Assume first that there exists a solution H, • ■ ■, ifc to the PCP instance (n, {vi}i<n, {wi}i<n). 
Consider in the POpPDA the faulty run: 

Pf = qo{ijqc)j<Aifsriflwi^[p])p<m,^ )j<fe(/s i\T , 
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M Figure 10 A POpPDA for the proof of Theorem 23. 


and the correct run: 

Pc = qo{ijqc)j<ku{qsr{qf.v,^ [p])p<ii. )j<k{qs \\T ■ 

These two runs have the same observed sequence: 'P{pf) = V{pc) = ii ■ ■ with w = 

Wi^ ... Wi^ = Vi^ ... Vi^. Therefore, pf is an infinite ambiguous faulty run. Given that 
P(p/) > 0, we deduce that the POpPDA {A,'So:'P) is not IF-diagnosable. From Theorem 4, 
it is also neither lA-diagnosable nor FA-diagnosable. 

Conversely, assume that the PCP instance {n,{vi}i<n,{u)i}i<n) has no solution. Independ¬ 
ently of that, observe that [] almost surely occurs in an infinite run of the pPDA A. Thus, 
for any e > 0, there exists N eN such that the measure of signalling runs with observable 
length N that reach configurations Iq) or (/g, Iq) by an event \\ is at least 1 -e. Consider 
a correct run pc with observable length N, ending in (gs,lo) and containing at least an 
occurrence of \\. Its observed sequence is of the form V{pc) = ii - ■ ■ ikVii ■ ■ - 1]™ for some 

ii,... ,ik,rn. Due to the fact that {n,{vi}i<n,{wi}i<n) has no solution, no faulty run can 
have the same observed sequence. Therefore, pc is surely correct. Symmetrically, any faulty 
run ending in (/s, Iq) after an occurrence of \\ is surely faulty. We thus conclude that, for any 
e > 0, there exists N eN such that P(FAmbjv tu CAmb^v) < e. As a consequence, the POpPDA 
{A,T,o,V) is FA-diagnosable. By Theorem 4 it is also lA-diagnosable and IF-diagnosable. ■* 

A similar undecidability result holds for a classe of POpPDA in which pop events are 
fully observable, and the number of phases is constant: 

► Theorem 24. The diagnosability problems are undecidable for POpPDA even when (1) the 
top of the stack is not updated, (2) every event labelling a pop transition is fully observable 
and corresponds to the popped symbol, and (3) every run consists of at most two phases. 
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Proof. The proof follows the same line as the one for Theorem 23. 

From an instance {n, {vi}i<n, {wiji^n) of PCP, let us define a pPDA A = (Q,S,r,(5, P) 
where: 

- Q = {qo,qs,fs,qeJe} u {gf I 1 < i < n, 1 < fc < £i} u {/f I 1 < i < n, 1 < A: < mj ; 

. T, = {l,...,n,\^,u,cA,a,b}', 

■ r = {1 ,... ,n,lo} with Px = {lo}; 

H 5 consists of the following transitions: 

{{qo,l,u,l,qs),{qo,l,^A,fs),{qe,-i-,\\A,qe),{feA,\\A,fe)} 
u {{q’y,z,v,[k],z,q^^^) I 1 < i < n,l < fc< 
u {{fi,z,Wi[k],z,fl^^'^) \ 1 < i < n,l < k < rrii, z e {l, 1, ■ ■ ■ ,'n}} 

U {{q^\z,Vi[£^],z,qs) I l<f <n,z6{l,l,...,n}} 

u I !<*<«, 

u {{qs,z,c,zx,ql) | z € {l, 1,..., n}, a: € {1,..., n}} 
u {{fs,z,c,zx,f^) |z6{i,l,...,n},a:6{l,...,n}} 
u {{qs,x,x,e,qe) |a;€{l,...,n}} 
u {(/^,a:,a;,e,/e) | a; e {1 ,...,n}} 
u {{qe,x,x,e,qe) |a;€{l,...,n}} 
u {{f^,x,x,e,fe) I a; e n}}. 

H P assigns arbitrary positive probabilities to transitions in S. 

We further consider the POpPDA {A, So, V) with So = S \ {c, u, f}, and the masking function 
satisfies V{u) = V{c) = V{i) = e and V{x) = x for any other event x. This POpPDA is 
represented in Figure 11. 


J-Oj J-o 


J-Oj J-o 



M Figure 11 A POpPDA for the proof of Theorem 24. 


Let us prove that the instance of the PCP is positive if and only if the POpPDA is IF-, 
I A- and FA-diagnosable. 
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Assume first that there exists a solution ii,... ,ik to the PCP instance (n, {vi}i<n, {wi}i<n)- 
Consider the faulty run: 

Pf - QO^fsic{f^^Wi^[p]')p<mi^fs')j<kiijfe')j<ki\\fe') ; 
and the correct run: 

Pc = (louqs{c{ql.Vi.[p\)p<i.^qs)j<k{ijqe)j<k{\\qeT ■ 

These two runs have the same observed sequence: V{pf) = V{pc) = wii.. .iki(^ with w = 
Wi^ ... Wii, = vq ... Vi^. Therefore, pf is an infinite ambiguous faulty run. Given that 
P(p/) > 0, we deduce that the POpPDA {A,T,o,V) is not IF-diagnosable. From Theorem 4, 
it is also neither lA-diagnosable nor FA-diagnosable. 

Conversely, assume that the PCP instance {n,{vi}i<n,{wi}i<n) has no solution. 

Independently of that, observe that [] almost surely occurs in an infinite run of the pPDA 
A. Thus, for any £ > 0, there exists e N such that the measure of signalling runs with 
observable length N that reach configurations (ge,io) or (/e,lo) by an event [\ is at least 
1 - s. Consider a correct run pc with observable length N ending in (ge, lo) and with an 
occurrence of []. Its observed sequence is of the form Vi^ ... ... ifc []™ for some ii,... ,ik,rn. 

Due to the fact that (n, {vi}i<n, {wi}i<n) has no solution, no faulty run can have the same 
observed sequence. Therefore, pc is surely correct. Symmetrically, any faulty run ending in 
ife, io) by an occurrence of I] is surely faulty. We thus conclude that, for any £ > 0, there 
exists 6 N such that P(FAmb 7 v w CAmbiv) < £• As a consequence, the POpPDA (A, So,P) 
is FA-diagnosable. By Theorem 4 it is also lA-diagnosable and IF-diagnosable. •» 



